The product does not properly verify that the source of data or communication is valid.
556 vulnerabilities with CWE-346
CVE-2023-47194
HIGH
Trend Micro Apex One < 14.0.12737 - Privilege Escalation via Origin Validation Error
CVSS 7.8
CVE-2023-47193
HIGH
Trend Micro Apex One < 14.0.12737 - Privilege Escalation via Origin Validation Error
CVSS 7.8
CVE-2023-20275
MEDIUM
Cisco ASA/FTD - Privilege Escalation
CVSS 4.1
CVE-2023-49805
MEDIUM
Uptime Kuma < 1.23.9 - Origin Validation Error in WebSocket Connection
CVSS 6.0
CVE-2023-49803
HIGH
@koa/cors < 5.0.0 - Origin Validation Error via Missing Allowed Origin Check
CVSS 8.6
CVE-2023-28794
MEDIUM
Zscaler Client Connector <1.3.1.6 - Privilege Escalation
CVSS 4.3
CVE-2023-5859
MEDIUM
Google Chrome < 119.0.6045.105 - Domain Spoofing via Picture In Picture Security UI
CVSS 4.3
CVE-2023-5858
MEDIUM
Google Chrome < 119.0.6045.105 - Security UI Obfuscation via WebApp Provider
CVSS 4.3
CVE-2023-5853
MEDIUM
Google Chrome < 119.0.6045.105 - Security UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2023-5851
MEDIUM
Google Chrome < 119.0.6045.105 - Origin Validation Error in Downloads
CVSS 4.3
CVE-2023-5718
MEDIUM
Vue.js Devtools - Unauthenticated Sensitive Data Exposure via postMessage API
CVSS 4.3
CVE-2023-28795
HIGH
Zscaler Client Connector <1.3.1.6 - Code Injection
CVSS 7.8
CVE-2023-44190
MEDIUM
Juniper Junos OS Evolved - Origin Validation Error in MAC Address Validation
CVSS 6.1
CVE-2023-44189
MEDIUM
Juniper Junos OS Evolved MAC Address Validation Origin Error
CVSS 6.1
CVE-2023-3654
CRITICAL
cashit! < 03.a06rks_2023.02.37 - Origin Validation Error via Host Header
CVSS 9.4
CVE-2023-2848
HIGH
movim < 0.22 - Cross-Site WebSocket Hijacking via Missing Header Validation
CVSS 8.0
CVE-2023-29505
MEDIUM
ManageEngine Network Configuration Manager 12.6.165 - Cross-site WebSocket Hijacking via WebSocket Endpoint
CVSS 4.3
CVE-2023-4045
MEDIUM
Firefox < 116 - Origin Validation Error via Offscreen Canvas
CVSS 5.3
CVE-2023-30949
MEDIUM
Palantir Slate < 6.207.0 - Origin Validation Error
CVSS 4.3
CVE-2023-2850
MEDIUM
NodeBB < 2.8.13 and 3.0.0-3.1.3 - Cross-Site WebSocket Hijacking via Missing Origin Validation
CVSS 4.7
CVE-2023-3581
MEDIUM
Mattermost 7.8.0-7.8.6 - WebSocket Origin Validation Bypass
CVSS 6.2
CVE-2023-21260
MEDIUM
Android - Origin Validation Error via Notification Access Permission Dialog
CVSS 5.5
CVE-2023-37210
MEDIUM
Firefox < 115.0 - Full-Screen Mode Spoofing via Alert and Prompt Calls
CVSS 6.5
CVE-2023-32223
HIGH
D-Link DSL-224 Firmware 3.0.10 - Authenticated Command Execution
CVSS 8.8
CVE-2023-32553
MEDIUM
Trend Micro Apex One < 14.0.12105 - Unauthenticated Sensitive Information Disclosure
CVSS 5.3
Details
Vulnerabilities
556